Skip to content
Noroxi

libreswan records

24 published records for vendor libreswan.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
70.8%
Median publish → KEV
No record has entered KEV

All records

24 records
  • CVE-2013-7283
    37Monitor

    Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact a

    CriticalCVSS 9.3No exploitEPSS 2%

    libreswan · libreswanJan 9, 2014

  • CVE-2020-1763
    31Monitor

    An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker

    HighCVSS 7.5No exploitEPSS 4%

    libreswan · libreswanMay 12, 2020

  • CVE-2016-5391
    31Monitor

    libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).

    HighCVSS 7.5No exploitEPSS 3%

    libreswan · libreswanJun 13, 2017

  • In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.

    HighCVSS 7.5No exploitEPSS 3%

    libreswan · libreswanMay 24, 2019

  • CVE-2016-5361
    31Monitor

    programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of

    HighCVSS 7.5No exploitEPSS 3%

    libreswan · libreswanJun 16, 2016

  • CVE-2016-3071
    31Monitor

    Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

    HighCVSS 7.5No exploitEPSS 3%

    libreswan · libreswanApr 18, 2016

  • Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKE

    HighCVSS 7.5No exploitEPSS 3%

    libreswan · libreswanJan 14, 2022

  • CVE-2023-2295
    30Monitor

    A vulnerability was found in the libreswan library.

    HighCVSS 7.5No exploitEPSS 2%

    libreswan · libreswanMay 17, 2023

  • pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive

    HighCVSS 7.5No exploitEPSS 1%

    libreswan · libreswanMay 28, 2023

  • IKEv2 Denial of Service via malformed fragmentation

    HighCVSS 7.5No exploitEPSS 1%

    libreswan · libreswanJul 2, 2026

  • Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorr

    MediumCVSS 6.5No exploitEPSS 2%

    libreswan · libreswanFeb 21, 2023

  • An issue was discovered in Libreswan before 4.12.

    MediumCVSS 6.5No exploitEPSS 1%

    libreswan · libreswanAug 25, 2023

  • An issue was discovered in Libreswan 3.x and 4.x before 4.12.

    MediumCVSS 6.5No exploitEPSS 1%

    libreswan · libreswanAug 25, 2023

  • An issue was discovered in Libreswan before 4.12.

    MediumCVSS 6.5No exploitEPSS 1%

    libreswan · libreswanAug 25, 2023

  • CVE-2024-3652
    26Monitor

    IKEv1 default AH/ESP responder can cause libreswan to abort and restart

    MediumCVSS 6.5No exploitEPSS 1%

    libreswan · libreswanApr 10, 2024

  • IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload

    MediumCVSS 5.9No exploitEPSS 0%

    libreswan · libreswanJul 2, 2026

  • IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload

    MediumCVSS 5.9No exploitEPSS 0%

    libreswan · libreswanJul 2, 2026

  • CVE-2013-4564
    21Monitor

    Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid maj

    MediumCVSS 5.0No exploitEPSS 3%

    libreswan · libreswanJan 7, 2014

  • CVE-2015-3204
    21Monitor

    libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bit

    MediumCVSS 5.0No exploitEPSS 3%

    libreswan · libreswanJul 1, 2015

  • CVE-2013-7294
    21Monitor

    The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (res

    MediumCVSS 5.0No exploitEPSS 3%

    libreswan · libreswanJan 16, 2014

  • CVE-2013-6467
    21Monitor

    Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 p

    MediumCVSS 5.0No exploitEPSS 2%

    libreswan · libreswanJan 26, 2014

  • CVE-2013-2052
    21Monitor

    Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allow

    MediumCVSS 5.1No exploitEPSS 2%

    libreswan · libreswanJul 9, 2013

  • CVE-2015-3240
    18Monitor

    The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of

    MediumCVSS 4.3No exploitEPSS 3%

    libreswan · libreswanNov 9, 2015

  • The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity

    LowCVSS 3.1No exploitEPSS 1%

    libreswan · libreswanJun 12, 2019